CVE-2022-2760: Medium severity octopus deploy vulnerability
In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2760?
CVE-2022-2760 has a medium severity rating due to the information disclosure it causes.
How do I fix CVE-2022-2760?
To fix CVE-2022-2760, update Octopus Deploy to a version that is not affected, specifically versions above 2022.1.3180, 2022.2.7965, or 2022.3.10405.
What versions of Octopus Deploy are affected by CVE-2022-2760?
Affected versions of Octopus Deploy are those from 2019.5.7 to 2022.1.3180, from 2022.2.0 to 2022.2.7965, and from 2022.3.0 to 2022.3.10405.
What kind of data can be exposed due to CVE-2022-2760?
CVE-2022-2760 can potentially expose the Space ID of spaces that the user does not have access to view.
Is there a workaround for CVE-2022-2760?
Currently, there is no documented workaround for CVE-2022-2760 and the recommended action is to apply the updates.